Bluetooth Vulnerability in Linux Kernel Affecting Request Handling
CVE-2026-23395
What is CVE-2026-23395?
A vulnerability in the Linux kernel's Bluetooth subsystem allows the acceptance of multiple connection requests without properly validating the command identifiers. This oversight can lead to an excessive allocation of resources, resulting in a buffer overflow condition. According to the Bluetooth specification, each request must utilize a unique identifier within a signaling channel. The vulnerability arises due to the failure to check for existing channels with the same identifier, potentially leading to system instability and unexpected behavior. The issue has been addressed to enforce proper validation of request identifiers.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Linux 15f02b91056253e8cdc592888f431da0731337b8
Linux 15f02b91056253e8cdc592888f431da0731337b8 < 2124d82fd25e1671bb3ceb37998af5aae5903e06
Linux 15f02b91056253e8cdc592888f431da0731337b8 < 6b949a6b33cbdf621d9fc6f0c48ac00915dbf514